---
id: CVE-2026-85450
title: >-
  MOOS core-moos through 10.4.0 contains a denial of service vulnerability in
  the MOOSDB HTTP server that creates unbounded connections and threads without
  limits
summary: >-
  MOOS core-moos through 10.4.0 contains a denial of service vulnerability in
  the MOOSDB HTTP server that creates unbounded connections and threads without
  limits. Attackers can open many connections and send endless header data to
  exhaust…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
published: '2026-09-03'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:07:17.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85450'
references:
  - url: 'https://github.com/themoos/core-moos'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/DB/HTTPConnection.cpp#L167
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/core-moos/commit/dfef92b3bc31886bc47e4d680aef583b78cb8d72
    label: disclosure@vulncheck.com
  - url: 'https://github.com/themoos/core-moos/pull/79'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-http-server-resource-exhaustion
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.0063
epssPercentile: 0.48053
ingestedAt: '2026-09-08T20:10:03.162Z'
---

## Overview

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server threads and memory, causing service unavailability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
